CVE-2024-46507

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
08/05/2026
Last modified:
08/05/2026

Description

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:yeti-platform:yeti:*:*:*:*:*:*:*:* 2.0 (including) 2.1.12 (excluding)